Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-55707

CVE-2026-55707: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.1

    High [CVE-2026-55707] Shared-network consumer can re-scope another project's subnets via subnetpool onboarding

    CVE-2026-55707Source published Source updated

    In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers. An authorization bypass was found in the OpenStack Neutron subnetpool onboarding API endpoint (PUT /v2.0/subnetpools/{id}/onboard_network_subnets). When a caller supplies a network_id, the API only verifies that the network is visible to the caller but does not verify that the caller owns the subnets on that network. When a network is RBAC-shared or globally shared, any project member with network visibility can invoke the API to onboard another project's subnets…

    Affected products in this advisory
    • Red Hat OpenStack Platform 16.2
    • Red Hat OpenStack Platform 17.1
    • Red Hat OpenStack Platform 18.0
    Source-reported affected versions
    • < 28.0.2
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Restrict the subnetpool onboarding API to administrators only by adding the following to the Neutron policy configuration (policy.yaml): onboard_network_subnets: "role:admin" This prevents non-admin project members from using the onboard_network_subnets API while maintaining the functionality for cloud administrators. If the subnet onboarding feature is not needed in the deployment, the API can be fully disabled by setting the policy to deny all: onboard_network_subnets: "!"

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery